Apache Qpid contains a flaw that is triggered during the handling of a federation_tag attribute in an AMQP connection, which will cause the connection to become broker-to-broker rather than client-to-server. This will cause client ID's to no longer be checked, which will allow a remote attacker to bypass restrictions and gain link access.